Note: Please contact Sophos Professional Services if you require direct assistance with your specific environment.
The post explains how to configure untagged port to connect PC.
It applies to Sophos Switch firmware version 1.
In the example, we are going to untag VLAN 200 on Sophos Switch Port9 and Port10 to connect PCs, and tag VLAN 200 on Port1 to connect core switch.
Three steps are required:
VLAN ID needs to be untagged on egress traffic to PC.
Log on webadmin of Sophos Switch, go to Configure > VLAN settings > 802.1Q, and Add a new VLAN
Add a new VLAN 200, and name it as you prefer.
Then Edit the VLAN 200 we just created
Untag it on Port9 and Port10
By default, Sophos Switch put ingress traffic without VLAN ID to the default VLAN 1, as explained in Sophos Cloud Switch: PVID https://support.sophos.com/support/s/article/KB-000043521
In another word, by default, Sophos Switch put traffic received from PC to VLAN 1.
To change the behaviour, we need to change PVID on untagged ports.
In Sophos Switch webadmin, go to Configure > VLAN settings > PVID and ingress filter, check Port9 and Port10, and Edit them.
Set PVID to 200 on Port9 and Port10.
Tag a VLAN on port is quite straightforward
In webadmin of Sophos Switch, go to Configure > VLAN settings > 802.1Q, Edit VLAN 200
Tag it on Port1
2022-04-28, first edition